A new supply chain attack linked to North Korean hackers targeted the Rust programming ecosystem, specifically a popular crate called 'arrayref.' The malicious version, 'arrayref@0.3.10,' was published from the original maintainer's account on August 20, containing code to fetch a harmful binary. Other compromised crates were linked to the attack, and the Rust Security Response Team quickly removed the malicious packages.
The attack is attributed to the North Korean threat actor Sapphire Sleet, who also executed earlier supply chain attacks on the NPM registry. No evidence of exploitation has been found, and the original author of the 'arrayref' crate is likely compromised.